Key points
People
In almost every organization surveyed, CISOs are now — or soon will be — responsible for OT cybersecurity. It is also worth noting that more OT cybersecurity professionals now come from IT security leadership rather than from the operations team.
Cybersecurity incidents
While the number of organizations that suffered no intrusion improved sharply year over year (from 6% in 2022 to 25% in 2023), there is still significant room for improvement. In fact, three quarters of OT organizations reported at least one intrusion in the past year, and nearly a third reported being hit by ransomware (32%, unchanged from 2022). Malware and phishing intrusions rose 12% and 9% respectively.
How cybersecurity helps
The survey results show that cybersecurity solutions continue to contribute to the success of most (76%) OT professionals, particularly by improving efficiency (67%) and flexibility (68%). The data also shows, however, that solution sprawl makes it harder to consistently protect the converged IT/OT landscape.
An analysis of the 2023 data reveals four notable global trends:
- Intrusions declined overall due to fewer internal breaches, although ransomware and phishing remain significant threats. Rather than lower risk, this may reflect attackers taking a more targeted approach.
- Almost every organization has placed responsibility for OT cybersecurity under a CISO rather than an operations team or executive.
- Organizations rely on a wide range of solutions; point products and solution sprawl can make it harder to apply and enforce policy consistently.
- The number of respondents rating their maturity at Level 4 fell from 21% to 13%, while those placing it at Level 3 rose from 35% to 44% — a more realistic self-assessment.
Critical insights
1. Responsibility for OT cybersecurity shifts from OT staff to cybersecurity experts
People working in OT are found across most major industries: manufacturing, transportation, logistics, healthcare, pharmaceuticals, oil, gas, energy, utilities, chemicals, and water. They have traditionally been closely involved in cybersecurity purchasing decisions for their environments.
2. OT professionals rely on a range of solutions
Above all, they look for solutions that detect known vulnerabilities. One distinctive challenge is that downtime is usually far more critical than in IT: success is measured less by data confidentiality and integrity and more by the availability of critical systems, which puts a premium on response time.
3. The number of intrusions remains a problem
75% of organizations reported at least one intrusion in the past 12 months. The overall decline is attributed to fewer internal breaches, not fewer attacks. Malware and phishing remain the most common threats and both increased, but ransomware is still the biggest concern.
4. Average maturity is improving
Accurate self-assessment is a fundamental first step. Fewer companies describe their posture as highly mature (from 21% to 13%), while 44% place it at Level 3 (up from 35% the previous year).
Conclusion
The report shows organizations are prioritizing cybersecurity for OT environments — a necessary trend, given that 75% had to deal with at least one cyberattack in the past 12 months. OT cybersecurity is maturing and incidents appear to be declining, but there is still a long way to go to adequately protect against the most common malware, such as ransomware.
